Merikbest Ecommerce Spring Reactjs File Upload Path Traversal Vulnerability

Vulnerability

A critical path traversal vulnerability has been identified in the Merikbest Ecommerce Spring Reactjs application, in versions prior to the commit 464e610bb11cc2619cf6ce8212ccc2d1fd4277fd. The issue arises in the File Upload Endpoint, specifically within the '/api/v1/admin/' route. The vulnerability allows for manipulation of the 'filename' argument, potentially leading to unauthorized access to files on the server. This vulnerability can be exploited remotely.

Impact

Exploitation of this vulnerability allows for path traversal, which could lead to unauthorized file access on the server.

Reproduction

The vulnerability can be reproduced by sending a request to the '/api/v1/admin/' endpoint with a crafted 'filename' argument that includes path traversal sequences. This will bypass normal file upload restrictions and access files outside the intended directory.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.